Memory Corruption Vulnerability Affects Firefox and Thunderbird
CVE-2024-11704
Currently unrated 🤨
Summary
A double-free issue could have occurred in sec_pkcs7_decoder_start_decrypt()
when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Affected Version(s)
Firefox < 133
Thunderbird < 133
Refferences
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Ronald Crane